CompTIA PenTest+ Certification - PT0-001 Free Exam Questions

QUESTION NO: 1
A consultant is identifying versions of Windows operating systems on a network Which of the following Nmap commands should the consultant run?

Correct Answer: A Vote an answer
QUESTION NO: 2
A penetration tester discovers an anonymous FTP server that is sharing the C:\drive. Which of the following is the BEST exploit?

Correct Answer: C Vote an answer
QUESTION NO: 3
A company planned for and secured the budget to hire a consultant to perform a web application penetration test. Upon discovered vulnerabilities, the company asked the consultant to perform the following tasks:
* Code review
* Updates to firewall setting

Correct Answer: B Vote an answer
QUESTION NO: 4
An energy company contracted a security firm to perform a penetration test of a power plant, which employs ICS to manage power generation and cooling. Which of the following is a consideration unique to such an environment that must be made by the firm when preparing for the assessment?

Correct Answer: B Vote an answer
QUESTION NO: 5
A penetration tester is performing a code review against a web application Given the following URL and source code:

Which of the following vulnerabilities is present in the code above?

Correct Answer: D Vote an answer
QUESTION NO: 6
A penetration tester generates a report for a host-based vulnerability management agent that is running on a production web server to gather a list of running processes. The tester receives the following information.

Which of the following processes MOST likely demonstrates a lack of best practices?

Correct Answer: C Vote an answer
QUESTION NO: 7
Consumer-based IoT devices are often less secure than systems built for traditional desktop computers.
Which of the following BEST describes the reasoning for this?

Correct Answer: B Vote an answer
QUESTION NO: 8
A penetration tester has compromised a Windows server and is attempting to achieve persistence. Which of the following would achieve that goal?

Correct Answer: C Vote an answer
QUESTION NO: 9
A client needs to be PCI compliant and has external-facing web servers. Which of the following CVSS vulnerability scores would automatically bring the client out of compliance standards such as PCI 3.x?

Correct Answer: D Vote an answer
QUESTION NO: 10
After performing a security assessment for a firm, the client was found to have been billed for the time the client's test environment was unavailable. The client claims to have been billed unfairly. Which of the following documents would MOST likely be able to provide guidance in such a situation?

Correct Answer: C Vote an answer
QUESTION NO: 11
While engaging clients for a penetration test from highly regulated industries, which of the following is usually the MOST important to the clients from a business perspective?

Correct Answer: A Vote an answer
QUESTION NO: 12
Joe, an attacker, intends to transfer funds discreetly from a victim's account to his own. Which of the following URLs can he use to accomplish this attack?

Correct Answer: B Vote an answer

QUALITY AND VALUE

Actual4test Practice Exams are written to the highest standards of technical accuracy, using only certified subject matter experts and published authors for development - no all study materials.

Tested and Approved

We are committed to the process of vendor and third party approvals. We believe professionals and executives alike deserve the confidence of quality coverage these authorizations provide.

Easy to Pass

If you prepare for the exams using our Actual4test testing engine, It is easy to succeed for all certifications in the first attempt. You don't have to deal with all dumps or any free torrent / rapidshare all stuff.

Try Before Buy

Actual4test offers free demo of each product. You can check out the interface, question quality and usability of our practice exams before you decide to buy.